AP2 Protocol
AP2 explained: intent and cart mandates, verifiable credentials, its move to the FIDO Alliance and how it pairs with x402 for settlement.
What is AP2?
The Agent Payments Protocol (AP2) answers the question every bank, merchant and regulator asks about AI shopping agents: did a human actually approve this purchase? Google announced it in September 2025 with more than 60 partners. In April 2026 Google handed it to the FIDO Alliance, the standards body behind passkeys, so it is now a neutral standard.
AP2 does not move money by itself. It creates proof of consent, then hands off to traditional payment rails such as cards and bank transfers, or to x402. On the card side, UAE issuers are already preparing for agent-initiated transactions through Visa Agentic Ready, and some UAE gateways already accept the domestic Jaywan scheme online, as our guide to Jaywan e-commerce acceptance explains.
How It Works: Mandates
AP2 is built around three signed records, each a verifiable credential:
- Intent Mandate: the rules the user gave the agent (“find running shoes under $150 this week”).
- Cart Mandate: the exact items and price the user approved.
- Payment mandate: ties the chosen payment method to the approved cart.
Because each step is signed, you end up with a non-repudiable audit trail. When a customer says “my agent bought the wrong thing”, you can show exactly what was authorized.
AP2 v0.2 (April 2026) adds “Human Not Present” flows, where an agent completes a purchase later under rules the user set in advance.
AP2 and x402
The A2A x402 extension, built with Coinbase, the Ethereum Foundation, MetaMask and others, connects AP2 to x402. AP2 proves the spend was allowed and x402 settles it in stablecoins. This split between authorization and settlement is the main idea in our protocol comparison.
Use Cases
- Delegated shopping: agents that buy within limits the user set
- Scheduled purchases: “buy when the price drops below X” with a signed intent
- Regulated flows: a consent record that compliance teams can audit
- Dispute handling: evidence of what was approved when something goes wrong
Our AP2 Services
- Mandate design: which limits and approvals belong in Intent vs Cart Mandates
- Integration: AP2 with your existing checkout or with x402 settlement
- Security audit: mandate validation, replay and spend-control review
Last updated October 9, 2026
Frequently Asked Questions
What is AP2?
AP2, the Agent Payments Protocol, is an open protocol Google announced on September 16, 2025 with more than 60 partners. It proves that a human actually authorized what an AI agent is buying, using signed mandates. It works as an extension of A2A and MCP.
Who governs AP2 now?
Google donated AP2 to the FIDO Alliance on April 28, 2026, the same group behind passkeys. Google released AP2 v0.2 at the same time, which adds support for payments where the human is not present.
What is the difference between an Intent Mandate and a Cart Mandate?
An Intent Mandate records the rules a user gave the agent, such as a price limit or a deadline. A Cart Mandate records the exact items and price the user approved. Both are signed verifiable credentials, so together they give a tamper-evident audit trail of who approved what.
Does AP2 move money?
No. AP2 is an authorization layer. It proves consent, then hands off to a payment method to move the money. The A2A x402 extension, built with Coinbase and others, connects AP2 mandates to x402 stablecoin settlement.
Get Started for Free
Schedule a free consultation with our payment infrastructure team. 30-minute call, actionable results in days.
Every engagement is scoped by our principal architect, Adrian Vale: 20+ years in production engineering, 40+ professional certifications. Meet Adrian
Talk to an Expert